Observed this in our environment the other day. The phishing link obfuscation using google translate is interesting. Basically adding your phishing url (reddit in this case) ie https://t.co/61UxVC6xpl can bypass email filtering since the TLD is .goog and likely considered "safe"
"Checking the registry and network traffic, we could identify ranges they scanned. They most likely ran several scans in Advanced IP scanner. We found evidence of scans for private IP ranges as well as multiple public IP ranges belonging to Microsoft and other entities..."
What I learnt today:
When NetScan is executed with the ‘Check for write access’ option enabled, a ‘delete[.]me’ file is created then deleted on discovered shares. [1]
Thanks, The DFIR Report - this is exactly what we are seeing in a recent case. I owe you one 🍻
[1] https://t.co/RcfTnnxoZy
We found a way to access Max Verstappen's passport, driver's license, and personal information. Along with every other @Formula1 driver's sensitive data.
It took us 10 minutes using one simple security flaw 🧵
🆕Recent additions to https://t.co/c2bs1AaVPZ:
• iscsicpl.exe for DLL exec+UAC bypass
• eudcedit.exe for UAC bypass
• reset.exe/change.exe/query.exe for proxy exec
• pixtool.exe/applauncher.exe/mpiexec.exe for dev tool proxy exec
⭐Nearly 8,000 GitHub stars - thank you all!